IntelFreed Cybersecurity Intelligence Weather Report

LATEST

Aggregated cybersecurity reporting, advisories and research. 1,057 matching records.
AUTO-POLL // 2026-08-30 10:15 UTC
CYBER INTEL TEMPERATURE
TODAY'S AGGREGATED INTELLIGENCE
COOL
COOL WARM ELEVATED HOT CRITICAL
P5 / P100
7-DAY C.I.T. REPORT
CYBER CONDITIONS // DAILY C.I.T. READINGS
TODAY → 6 DAYS AGO
TODAY
Aug 30

RANSOMWARE
P5
P5
COOL // 3 ARTICLES
SAT
Aug 29

RANSOMWARE
P9
P9
COOL // 8 ARTICLES
FRI
Aug 28

RANSOMWARE
P8
P8
COOL // 47 ARTICLES
THU
Aug 27

RANSOMWARE
P4
P4
COOL // 48 ARTICLES
WED
Aug 26

RANSOMWARE
P4
P4
COOL // 46 ARTICLES
TUE
Aug 25

ACTIVE EXPLOITATION
P4
P4
COOL // 40 ARTICLES
MON
Aug 24

RANSOMWARE
P4
P4
COOL // 34 ARTICLES
RESET
2026-08-26 16:00 UTC
Vendor Research

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco Security Advisories · indexed 2026-08-26 16:20 UTC

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Desk Phone 9800, 7800 and 8800, and 8875 Series Software IOS XR Software (security hardening release) Nexus 9000 Series Switches Silicon One Secure Email To fully remediate vulnerabilities to be disclosed on September 2, 2026, Cisco strongly recommends that customers upgrade to …

AppleDFIRNetwork SecurityVulnerabilities
P0
2026-08-26 15:58 UTC
Community

Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

SANS Internet Storm Center · indexed 2026-08-26 16:15 UTC

A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"?  Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose).  Yes, we trust our people, but if they've moved on to other roles or to other organizations, they change from "our people" to "used to be our people".  
 Also,…

Microsoft
P0
2026-08-26 15:35 UTC
Security Journalism

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 17:50 UTC

Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active Iranian APT groups in 2026. Nimbus Manticore (aka

APT / Nation-StateMalwareSecurity Research
P0
2026-08-26 15:19 UTC
Security Journalism

Boston Scientific says cyberattack disrupted operations globally

BleepingComputer · Bill Toulas · indexed 2026-08-26 15:30 UTC

Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]

P0
2026-08-26 14:01 UTC
Security Journalism

Snowflake ends service-account passwords. Now comes the hard part

BleepingComputer · Sponsored by Token Security · indexed 2026-08-26 14:15 UTC

Snowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. [...]

P0
2026-08-26 13:44 UTC
Security Journalism

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 14:20 UTC

Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that's used as a proxy to redirect Microsoft 365 sign-ins, while capturing authenticated sessions in the process. In a report shared with The Hacker News ahead of publication, Island characterized the $320/month service as a subscription-based phishing platform that

MicrosoftPhishingSecurity Research
P0
2026-08-26 13:07 UTC
Security Journalism

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 14:20 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were fully compromised at the domain level, and in both, the red team also

P0
2026-08-26 11:55 UTC
Security Journalism

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 13:10 UTC

The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the mwEmbedLoader.php endpoint of the mwEmbed player

Cloud SecurityVulnerabilitiesCVE-2026-19912CVE-2026-19913
P5
2026-08-26 11:36 UTC
Security Journalism

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 12:00 UTC

The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then waits for a human to decide if it should escalate to an investigation. Given the volume of

DFIR
P0
2026-08-26 10:27 UTC
Security Journalism

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 10:35 UTC

Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an

P0
2026-08-26 09:38 UTC
Security Journalism

OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 10:35 UTC

OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts "were being used to promote the International Burke Institute (IBI), a

AI SecurityNetwork Security
P0
2026-08-26 09:00 UTC
Vendor Research

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…

APT / Nation-StateData BreachesDFIRMicrosoftNetwork SecurityPhishingRansomwareThreat ActorsThreat IntelligenceVulnerabilities
P45
2026-08-26 08:44 UTC
Other

U.S. CISA adds Gitea flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 10:00 UTC

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Gitea flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-60004 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Gitea is an open-source platform for […]

VulnerabilitiesCVE-2026-60004
P35
2026-08-26 08:30 UTC
Other

88 ID Verification Breaches Show the Cost of Collecting Identity Data

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 08:40 UTC

88 ID-verification breaches exposed billions of records, highlighting the growing risks of collecting sensitive identity and biometric data. A new report from Mysterium VPN compiles 88 documented incidents since 2011 where data collected specifically to verify someone’s identity or age got breached, exposed, or sold. The confirmed and researcher-verified total sits at 2.15 billion records, […]

Network Security
P0
2026-08-26 08:08 UTC
Other

WhatsApp Adds Stronger Security as Passkeys Hit 1 Billion

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 08:40 UTC

WhatsApp says 1 billion users now use passkeys, while stronger two-step verification and caller context add new layers of account protection. WhatsApp has reached a significant security milestone: more than one billion people now use passkeys to protect access to their accounts. At the same time, Meta is adding stronger two-step verification and more information […]

P0
2026-08-26 08:00 UTC
Security Journalism

Nigeria Looks to Sovereign Cloud for Cyber, National Security

Dark Reading · Robert Lemos · indexed 2026-08-26 08:05 UTC

The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.

P0
2026-08-26 07:54 UTC
Security Journalism

INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC

An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African criminal networks – such as the Black Axe and other similar groups," INTERPOL said. "These groups are

CybercrimeLaw Enforcement
P0
2026-08-26 07:17 UTC
Other

Operation Jackal: 58 Arrests Expose the Money Laundering Machine Behind Global Scams

Security Affairs · Pierluigi Paganini · indexed 2026-08-26 07:40 UTC

INTERPOL’s Operation Jackal IV made 58 arrests and exposed global networks laundering money from scams, fraud and sextortion. INTERPOL announced that Operation Jackal IV, running from November 2025 to June 2026, led to 58 arrests and identified 263 suspects tied to West African organized crime networks, groups like Black Axe that are responsible for a […]

CybercrimeLaw Enforcement
P0
2026-08-26 07:12 UTC
Security Journalism

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 08:50 UTC

An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&

MalwareMicrosoft
P0
2026-08-26 06:27 UTC
Security Journalism

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-26 07:10 UTC

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an attacker with ordinary write access to a repository to execute arbitrary shell commands as the

VulnerabilitiesCVE-2026-60004
P45
3 4 5 6 7